outline-agent
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes multiple external documents (idea.md, experimental_log.md, template.tex, conference_guidelines.md) provided in the workspace. This presents a surface for indirect prompt injection where adversarial content within these documents could attempt to influence the agent's logic. However, the skill mitigates this by applying a specific 'Anti-Leakage Prompt' and validating all output against a strict JSON schema.
- Ingestion points: workspace/inputs/idea.md, workspace/inputs/experimental_log.md, workspace/inputs/template.tex, workspace/inputs/conference_guidelines.md.
- Boundary markers: The instructions mandate prepending an anti-leakage-prompt.md to the system message.
- Capability inventory: File read/write operations within the workspace and execution of a local validation script.
- Sanitization: The output is strictly constrained to a JSON schema and verified by scripts/validate_outline.py.
- [COMMAND_EXECUTION]: The skill executes a local utility script, scripts/validate_outline.py, using the system Python interpreter to validate the generated outline. This is an intended part of the workflow and operates on the skill's own output.
Audit Metadata